Courseiva
Identity and Access ManagementhardMultiple ChoiceObjective-mapped

CISSP Identity and Access Management Practice Question

An organization discovers that a former employee's account is still active and has been used to access sensitive data. This is an example of which type of risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Orphaned account

An orphaned account is one that remains active after an employee has left, posing a security risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Orphaned account

    Why this is correct

    An orphaned account is an active user account that no longer has an associated legitimate user, typically because the employee has left the organization but their account was not properly deprovisioned or disabled. This oversight creates a significant security vulnerability, as the account could be exploited by an attacker or the former employee themselves to gain unauthorized access to systems and data. The discovery of a former employee's active account directly indicates a failure in the organization's identity and access management offboarding process.

  • Privilege escalation

    Why it's wrong here

    Privilege escalation refers to the act of an attacker or user gaining higher access rights than they were originally authorized for, often by exploiting system vulnerabilities or misconfigurations. While a former employee *could* attempt to escalate privileges if they regained access, the core issue described is the *existence* of their account post-employment, not the act of increasing permissions from an already established, lower-level access. The problem is the account's continued presence, not a change in its privilege level.

  • Social engineering

    Why it's wrong here

    Social engineering involves manipulating individuals into performing actions or divulging confidential information, often through psychological tactics like phishing, pretexting, or baiting. This method targets human vulnerabilities rather than technical system flaws or administrative oversights. The scenario describes a technical oversight in account deprovisioning, not a situation where an individual was tricked into creating or maintaining the former employee's account, nor does it describe how the account was discovered.

  • Insider threat

    Why it's wrong here

    An insider threat typically originates from a current employee, contractor, or business partner who has authorized access to an organization's assets and misuses that access, either intentionally or unintentionally, to negatively affect the organization. While a former employee with an active account could pose a risk, the term 'insider threat' specifically implies a *current* trusted relationship. The primary issue here is the failure to revoke access for someone who is no longer an insider, rather than malicious activity by a current one.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.